{"id":"GHSA-9gxr-rhx6-4jgv","aliases":[],"url":"https://o3.security/vulnerability/GHSA-9gxr-rhx6-4jgv","summary":"Sandbox Breakout / Prototype Pollution in notevil","details":"Versions of `notevil` prior to 1.3.3 are vulnerable to Sandbox Escape leading to Prototype pollution. The package fails to restrict access to the main context, allowing attacker to add or modify an object's prototype.\n\nEvaluating the payload ```try{a[b];}catch(e){e.constructor.constructor('return __proto__.arguments.callee.__proto__.polluted=true')()}``` add the `polluted` property to Function.\n\n\n## Recommendation\n\nUpgrade to version 1.3.3 or later.","published":"2020-09-04T15:18:57Z","modified":"2020-08-31T18:55:36Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"notevil","fixedVersion":"1.3.3"}],"fix":null,"references":[{"type":"WEB","url":"https://www.npmjs.com/advisories/1338"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2020-08-31T18:55:36Z"}}